Legal

Privacy Policy

Last updated: 20 August 2026

Your royalty statements are among the most sensitive financial records you have. This policy says exactly what Rekon does with them: what we collect, what we deliberately throw away, who else ever sees it, how long we keep it, and what you can ask us to do.

1. Who we are

Rekon is operated from Antwerpen, Belgium, and is the controller of the personal data described here.

Contact: privacy@rekonroyalties.com

Because Rekon is established in the EU, the GDPR applies to everything we do with your data — wherever in the world you are. Customers in the UK, Canada, Australia and South Africa also have rights under their own local law; see §10.

2. What we collect

  • Your account: Name, email address, a hash of your password (never the password itself), and your settings — including the currency you want figures shown in.
  • Your royalty statements: The files you upload, forward or that reach us through a connection, and the data we read from them: earnings by track and territory, track and release metadata, identifiers such as ISRC and ISWC, and the periods each statement covers.
  • Connection details: For each source: which platform, how it delivers, when it last worked, and — for the email route — the sending domain and a one-way hash of the sender’s address. We deliberately do not store the full sender address.
  • Usage and security data: Technical logs, IP address, browser type, and records of failed authentication or rate-limiting, used to detect abuse.
  • Payment data: Handled by Stripe. Card numbers never reach Rekon.
  • Saved sign-in details, where you choose to save them: See §5. This is not currently enabled for any platform.

What we deliberately remove. Royalty statements often carry more than royalties. Before a statement is stored, we strip out bank account numbers, IBANs, tax and national identification numbers, dates of birth, postal addresses and contact details. They are replaced with a marker so you can see something was removed. This happens whichever route the statement arrived by, and we record how many values were removed from each statement.

We do not ask for, and do not hold, your bank details. Rekon never pays you and never moves money. Your payers pay you exactly as they do now.

2.2 Cookies and similar storage on your device

Some of what Rekon stores lives on your own device. Permission to put it there is a separate question from what we then do with it, and only one thing in this list is optional — the analytics. We ask before storing it, and nothing optional is stored until you answer. Everything else below is needed to run the service you asked for.

WhatWhyHow long
Sign-inKeeps you signed in, and shared across the app and Label HQ so one login covers bothUp to 12 months
Analytics — PostHog (optional)Which parts of the app are used, so we know what to fix. Linked to your account, not anonymous12 months
Your answer to the cookie questionSo we do not ask again on every visitUntil you change it
Payments — StripeFraud prevention during checkout. Set only on the checkout pageUp to 12 months
Bot protection — CloudflareBlocks automated abuse of the siteShort-lived
Small preferencesAn invite link you followed, a plan you picked, a prompt you dismissedUntil used or cleared

You can change your answer at any time — from Settings, Privacy if you are signed in, or from the “Cookie choices” link at the bottom of any page. Changing it to no stops the collection and removes the analytics cookie. It does not delete what was already collected; ask us and we will.

2.1 Other people's data in your statements

Your statements name people who are not you — co-writers, producers, publishers, performers. We process that data solely to show you and them what a statement says about the work. We do not build profiles of those people, contact them, or use their data for anything else.

If you are named in a statement someone else uploaded and want to know what we hold, write to the address in §1.

3. Why we are allowed to process it

  • Performance of a contract (Art. 6(1)(b)): Covers almost everything: reading your statements, showing your earnings, running connections, and generating split sheets. It is what you asked us to do.
  • Legitimate interests (Art. 6(1)(f)): Covers security logging and abuse detection — keeping the service safe. It does not cover analytics: anything stored on your device needs your permission first, whatever the reason for it, and legitimate interests is not a route to that.
  • Legal obligation (Art. 6(1)(c)): Covers billing records we must keep for tax purposes.
  • Consent (Art. 6(1)(a)): Covers analytics, anything else stored on your device that is not needed to run the service, and marketing. Where we rely on consent you can withdraw it at any time, and doing so does not affect anything done before. See §2.2.

On saved sign-ins specifically: we rely on contract, not consent. The per-platform authorisation you give is an instruction, and it is recorded as one. This matters because it changes what withdrawal means: removing a saved sign-in stops us using it and destroys it, but does not unwind statements already collected.

4. Automated analysis

Rekon analyses your catalogue automatically to flag possible missing registrations, unregistered works and apparent discrepancies. No person reviews each result before you see it.

These are prompts for you to investigate, not decisions about you. They do not determine your access to anything, and they produce no legal or similarly significant effect. You can ask us to explain any result.

5. Saved sign-in details

Not currently enabled for any platform. Described so this policy covers it before it is ever offered.

Where a platform offers no other way to reach your statements, you may choose to save your sign-in details so Rekon can collect them for you.

How they are protected. Your details are encrypted in your own browser, before anything is sent to us. The key that would open them is itself locked to a separate, isolated system that has no access to our database. Our servers and our database therefore hold data they cannot read, and neither can we.

The practical consequence: someone who compromised our database, or our application, would not obtain your password. Two separate systems would have to fail together.

Retention. A saved sign-in unused for 180 days is destroyed automatically.

Destruction. Removing a saved sign-in, withdrawing the authorisation, or closing your account destroys the key that decrypts it. That makes it permanently unrecoverable — including from backups, which cannot be edited.

Every access is logged: which credential, when, and why. The log never contains the credential or anything derived from it.

6. Who else sees your data

We never sell your data. Not to data brokers, not to anyone.

We name our processors rather than describing them by category, because you cannot assess a processor you have not been told about:

ProcessorWhat it doesWhere
Supabase (on AWS)Database, sign-in, file storageIreland
CloudflareApplication hosting; mail routing for statement addressesGlobal edge network
StripePayments. Card details go to Stripe, never to usUnited States
ResendTransactional emailUnited States
PostHogProduct analytics and security loggingEuropean Union
DocuSealSplit-sheet signaturesEuropean Union

Each is bound by a Data Processing Agreement. This list changes when our infrastructure does, and we update it here.

Collaborators you invite see the project data you share with them. Co-signers on a split sheet see the identifiers needed to sign it.

Platforms you connect to are independent controllers in their own relationship with you. What they do with your data is governed by their terms, not ours.

7. Where your data is

Your data is hosted in the European Union. Two processors are in the United States — Stripe and Resend — and those transfers rely on Standard Contractual Clauses.

If you are outside the EU, your data is transferred into the EU, which means it is protected by the GDPR: for most customers this is a higher standard than their local law requires, not a lower one.

8. How long we keep it

WhatHow long
Account and statementsUntil you delete them or close your account
Saved sign-ins180 days unused, then destroyed automatically
Statement emails held for review30 days
Security and access logs12 months
Billing recordsAs tax law requires (typically 7–10 years)

Closing your account deletes your data, including files in storage. Where something cannot be deleted outright — a backup already taken — we destroy the key instead, which is what makes the data unrecoverable.

9. Your rights

You can access your data, correct it, delete it, export it in a machine-readable format, object to processing based on legitimate interests, restrict processing while a dispute is resolved, and withdraw consent where we rely on it.

Most of these are self-service in the app; export and deletion both are. For anything else, write to the address in §1. We respond within one month.

9.1 Complaining to us

If you are unhappy with how we handle your data, tell us first — you have a right to complain directly to us. Write to privacy@rekonroyalties.com or use any other route you normally reach us by; we will accept a complaint however it arrives.

We will acknowledge within 5 working days and give you a substantive response within 30 days. If it will take longer, we will tell you why and when to expect an answer.

9.2 Complaining to a regulator

You can complain to a supervisory authority at any time, whether or not you have come to us first.

  • EU: Your local authority, or the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), which is our lead supervisory authority.
  • UK: The Information Commissioner’s Office.
  • Canada: The Office of the Privacy Commissioner, or the Commission d’accès à l’information in Québec.
  • Australia: The Office of the Australian Information Commissioner.
  • South Africa: The Information Regulator.

10. Regional information

The rest of this policy applies to everyone. These are the additions for particular countries.

  • United Kingdom: UK GDPR applies to you and your rights are as set out in §9, including the right in §9.1 to complain to us directly before going to the ICO.
  • Québec, Canada: Our privacy officer can be reached at privacy@rekonroyalties.com. Your data is transferred outside Québec, to the European Union; we have assessed that transfer and consider the protection there adequate. You have the right to ask for that assessment.
  • Australia: The Australian Privacy Principles apply to our handling of your data. §4 describes the automated analysis Rekon performs. Your data is held overseas, in the European Union.
  • South Africa: Where POPIA applies to our processing, our Information Officer can be reached at privacy@rekonroyalties.com, and your data is transferred to the European Union under a law providing substantially similar protection.

11. Security

Data is encrypted in transit and at rest. Access to production systems is restricted and requires multi-factor authentication. Every table enforces per-account isolation at the database level, so one customer’s query cannot reach another’s data.

Saved sign-ins are protected as described in §5.

If a breach puts your rights at risk, we will tell you — and the regulator within 72 hours, as the law requires.

12. Children

Rekon is not for anyone under 16, and we do not knowingly collect their data. If you believe we have, tell us and we will delete it.

13. Changes

We may update this policy. For minor changes we update this page and its date. For changes that materially affect how your data is handled, we will tell you before they take effect.